Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Published Nov 18, 2020
7.5
HIGHCVSS 3.1
EPSS 2.34%
Description
Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file.
Affected products
-
- Version 0StatusaffectedConstraints<1.14.12
- Version 1.15.0-0StatusaffectedConstraints<1.15.5
- Version
-
- Version 0StatusaffectedConstraints<1.14.12
- Version 1.15.0-0StatusaffectedConstraints<1.15.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Go toolchain | Cmd/cgo | unaffected |
| |||||||||
| Go toolchain | Cmd/go | unaffected |
|
Configuration 2
- 32
- 33
Configuration 3
- n/a
- n/a
No data.
Openshift Serveless 1.12
openshift-serverless-1/client-kn-rhel8:0.18.4-2
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8:0.18.6-2
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/eventing-controller-rhel8:0.18.6-2
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/eventing-in-memory-channel-controller-rhel8:0.18.6-2
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8:0.18.6-2
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/eventing-mtbroker-filter-rhel8:0.18.6-2
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/eventing-mtbroker-ingress-rhel8:0.18.6-2
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/eventing-mtchannel-broker-rhel8:0.18.6-2
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/eventing-mtping-rhel8:0.18.6-2
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/eventing-storage-version-migration-rhel8:0.18.6-2
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/eventing-sugar-controller-rhel8:0.18.6-2
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/eventing-webhook-rhel8:0.18.6-2
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/ingress-rhel8-operator:1.12.0-2
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/kn-cli-artifacts-rhel8:0.18.4-2
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/knative-rhel8-operator:1.12.0-3
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/kourier-control-rhel8:0.18.0-2
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/serverless-operator-bundle:1.12.0-5
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/serverless-rhel8-operator:1.12.0-4
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/serving-activator-rhel8:0.18.2-3
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/serving-autoscaler-hpa-rhel8:0.18.2-3
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/serving-autoscaler-rhel8:0.18.2-3
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/serving-controller-rhel8:0.18.2-3
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/serving-queue-rhel8:0.18.2-3
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/serving-storage-version-migration-rhel8:0.18.2-3
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/serving-webhook-rhel8:0.18.2-3
Fixed · RHSA-2021:0146
Openshift Serveless 1.12
openshift-serverless-1/svls-must-gather-rhel8:1.12.0-2
Fixed · RHSA-2021:0146
Openshift Serverless 1 on RHEL 8
openshift-serverless-clients-0:0.18.4-2.el8
Fixed · RHSA-2021:0145
Red Hat Developer Tools
go-toolset-1.14-0:1.14.12-1.el7_9
Fixed · RHSA-2020:5333
Red Hat Developer Tools
go-toolset-1.14-golang-0:1.14.12-1.el7_9
Fixed · RHSA-2020:5333
Red Hat Enterprise Linux 8
go-toolset:rhel8-8030020201118084734.58e1918e
Fixed · RHSA-2020:5493
Distributed Tracing Jaeger 1
distributed-tracing/jaeger-all-in-one-rhel7
Not affected
Distributed Tracing Jaeger 1
distributed-tracing/jaeger-all-in-one-rhel8
Not affected
Distributed Tracing Jaeger 1
jaeger-rhel7-operator
Not affected
Distributed Tracing Jaeger 1
jaeger-rhel8-operator
Not affected
OpenShift Serverless
knative-eventing
Affected
OpenShift Service Mesh 1
kiali
Not affected
OpenShift Service Mesh 1
servicemesh
Not affected
OpenShift Service Mesh 1
servicemesh-operator
Not affected
OpenShift Service Mesh 2.0
kiali
Not affected
OpenShift Service Mesh 2.0
servicemesh
Not affected
OpenShift Service Mesh 2.0
servicemesh-operator
Not affected
Red Hat Ceph Storage 2
golang
Out of support scope
Red Hat Ceph Storage 2
grafana
Out of support scope
Red Hat Ceph Storage 3
golang
Out of support scope
Red Hat Ceph Storage 3
golang-github-prometheus-node_exporter
Not affected
Red Hat Ceph Storage 3
grafana
Not affected
Red Hat Ceph Storage 3
grafana-container
Not affected
Red Hat Ceph Storage 4
grafana
Not affected
Red Hat Ceph Storage 4
rhceph/rhceph-4-dashboard-rhel8
Not affected
Red Hat Enterprise Linux 7
gcc
Out of support scope
Red Hat Enterprise Linux 7
golang
Out of support scope
Red Hat OpenShift Container Platform 3.11
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 4
openshift
Not affected
Red Hat OpenShift Virtualization 2
kubevirt-virtctl
Not affected
Red Hat Openshift Container Storage 4
mcg
Not affected
Red Hat Openshift Container Storage 4
ocs4/cephcsi-rhel8
Not affected
Red Hat Openshift Container Storage 4
ocs4/mcg-rhel8-operator
Not affected
Red Hat Openshift Container Storage 4
ocs4/ocs-must-gather-rhel8
Not affected
Red Hat Openshift Container Storage 4
ocs4/ocs-rhel8-operator
Not affected
Red Hat Openshift Container Storage 4
ocs4/rook-ceph-rhel8-operator
Not affected
Red Hat Storage 3
etcd
Not affected
Red Hat Storage 3
golang
Will not fix
Red Hat Storage 3
grafana
Not affected
Red Hat Storage 3
heketi
Not affected
Red Hat Storage 3
multi-cloud-object-gateway-cli
Not affected
Red Hat Storage 3
noobaa-operator-container
Not affected
Red Hat Storage 3
rhgs3/rhgs-gluster-block-prov-rhel7
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Openshift Serveless 1.12 | openshift-serverless-1/client-kn-rhel8:0.18.4-2 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8:0.18.6-2 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/eventing-controller-rhel8:0.18.6-2 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/eventing-in-memory-channel-controller-rhel8:0.18.6-2 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8:0.18.6-2 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/eventing-mtbroker-filter-rhel8:0.18.6-2 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/eventing-mtbroker-ingress-rhel8:0.18.6-2 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/eventing-mtchannel-broker-rhel8:0.18.6-2 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/eventing-mtping-rhel8:0.18.6-2 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/eventing-storage-version-migration-rhel8:0.18.6-2 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/eventing-sugar-controller-rhel8:0.18.6-2 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/eventing-webhook-rhel8:0.18.6-2 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/ingress-rhel8-operator:1.12.0-2 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/kn-cli-artifacts-rhel8:0.18.4-2 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/knative-rhel8-operator:1.12.0-3 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/kourier-control-rhel8:0.18.0-2 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/serverless-operator-bundle:1.12.0-5 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/serverless-rhel8-operator:1.12.0-4 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/serving-activator-rhel8:0.18.2-3 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/serving-autoscaler-hpa-rhel8:0.18.2-3 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/serving-autoscaler-rhel8:0.18.2-3 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/serving-controller-rhel8:0.18.2-3 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/serving-queue-rhel8:0.18.2-3 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/serving-storage-version-migration-rhel8:0.18.2-3 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/serving-webhook-rhel8:0.18.2-3 | Fixed | RHSA-2021:0146 |
| Openshift Serveless 1.12 | openshift-serverless-1/svls-must-gather-rhel8:1.12.0-2 | Fixed | RHSA-2021:0146 |
| Openshift Serverless 1 on RHEL 8 | openshift-serverless-clients-0:0.18.4-2.el8 | Fixed | RHSA-2021:0145 |
| Red Hat Developer Tools | go-toolset-1.14-0:1.14.12-1.el7_9 | Fixed | RHSA-2020:5333 |
| Red Hat Developer Tools | go-toolset-1.14-golang-0:1.14.12-1.el7_9 | Fixed | RHSA-2020:5333 |
| Red Hat Enterprise Linux 8 | go-toolset:rhel8-8030020201118084734.58e1918e | Fixed | RHSA-2020:5493 |
| Distributed Tracing Jaeger 1 | distributed-tracing/jaeger-all-in-one-rhel7 | Not affected | n/a |
| Distributed Tracing Jaeger 1 | distributed-tracing/jaeger-all-in-one-rhel8 | Not affected | n/a |
| Distributed Tracing Jaeger 1 | jaeger-rhel7-operator | Not affected | n/a |
| Distributed Tracing Jaeger 1 | jaeger-rhel8-operator | Not affected | n/a |
| OpenShift Serverless | knative-eventing | Affected | n/a |
| OpenShift Service Mesh 1 | kiali | Not affected | n/a |
| OpenShift Service Mesh 1 | servicemesh | Not affected | n/a |
| OpenShift Service Mesh 1 | servicemesh-operator | Not affected | n/a |
| OpenShift Service Mesh 2.0 | kiali | Not affected | n/a |
| OpenShift Service Mesh 2.0 | servicemesh | Not affected | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-operator | Not affected | n/a |
| Red Hat Ceph Storage 2 | golang | Out of support scope | n/a |
| Red Hat Ceph Storage 2 | grafana | Out of support scope | n/a |
| Red Hat Ceph Storage 3 | golang | Out of support scope | n/a |
| Red Hat Ceph Storage 3 | golang-github-prometheus-node_exporter | Not affected | n/a |
| Red Hat Ceph Storage 3 | grafana | Not affected | n/a |
| Red Hat Ceph Storage 3 | grafana-container | Not affected | n/a |
| Red Hat Ceph Storage 4 | grafana | Not affected | n/a |
| Red Hat Ceph Storage 4 | rhceph/rhceph-4-dashboard-rhel8 | Not affected | n/a |
| Red Hat Enterprise Linux 7 | gcc | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | golang | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift | Not affected | n/a |
| Red Hat OpenShift Virtualization 2 | kubevirt-virtctl | Not affected | n/a |
| Red Hat Openshift Container Storage 4 | mcg | Not affected | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/cephcsi-rhel8 | Not affected | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/mcg-rhel8-operator | Not affected | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/ocs-must-gather-rhel8 | Not affected | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/ocs-rhel8-operator | Not affected | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/rook-ceph-rhel8-operator | Not affected | n/a |
| Red Hat Storage 3 | etcd | Not affected | n/a |
| Red Hat Storage 3 | golang | Will not fix | n/a |
| Red Hat Storage 3 | grafana | Not affected | n/a |
| Red Hat Storage 3 | heketi | Not affected | n/a |
| Red Hat Storage 3 | multi-cloud-object-gateway-cli | Not affected | n/a |
| Red Hat Storage 3 | noobaa-operator-container | Not affected | n/a |
| Red Hat Storage 3 | rhgs3/rhgs-gluster-block-prov-rhel7 | Not affected | n/a |
toolchain
Go
Introduced 0 Fixed 1.14.12toolchain
Go
Introduced 1.15.0-0 Fixed 1.15.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | toolchain | 0 | 1.14.12 |
| Go | toolchain | 1.15.0-0 | 1.15.5 |
Remediation
Red Hat statement
While OpenShift Container Platform (OCP), Red Hat OpenShift Jaeger (RHOSJ), OpenShift Service Mesh (OSSM), and OpenShift Virtualization all contain RPMs and containers which are compiled with a vulnerable version of Go, the vulnerability is specific to the building of Go code itself. Using `go get` or `go build` and as such, the relevant components have been marked as not affected. Additionally, only the main RPMs and containers for OCP, RHOSJ, OSSM, and OpenShift Virtualization are represented due to the large volume of not affected components. Red Hat Ceph Storage 3 ships the vulnerable version of go, and an attacker building go code on RHCS 3 could potentially exploit this vulnerability.
Red Hat mitigation
If it's possible to confirm that the Go project being built does not rely on any cgo code in the included dependencies, the env variable CGO_ENABLED=0 can be specified when using either `go get` or `go build`. For example: CGO_ENABLED=0 go get github.com/someproject This will not stop the files being downloaded but will stop any automatic complication of the cgo code, including inlined in the go file and separate .c files. Of course, this will only be effective if cgo is not relied upon in a given dependency and may not be appropriate in all scenarios.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:H/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 2.34% (0.02342) | 83.04th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.24% (0.02244) | 80.52th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.13% (0.00128) | 29.64th | v4 (v2025.03.14) |
| Jul 20, 2024 | 0.86% (0.00857) | 82.46th | v3 (v2023.03.01) |
| Jun 7, 2024 | 0.86% (0.00857) | 82.31th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.86% (0.00857) | 80.31th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.24% (0.00244) | 61.60th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.18% (0.00175) | 52.83th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.51% (0.02509) | 81.86th | v2 (v2022.01.01) |
| Dec 30, 2022 | 2.51% (0.02509) | 81.23th | v2 (v2022.01.01) |
| Dec 29, 2022 | 1.11% (0.01108) | 54.25th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.11% (0.01108) | 51.54th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.26% (0.07256) | 80.52th | v2 (v2022.01.01) |
| Feb 3, 2022 | 6.21% (0.06208) | 81.93th | v1 |
| Jan 6, 2022 | 6.21% (0.06208) | 81.75th | v1 |
| Jan 5, 2022 | 1.45% (0.01454) | 72.86th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.45% (0.01454) | 0.00th | v1 |
References (10)
- https://access.redhat.com/security/cve/CVE-2020-28366 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1897643 Issue Tracking
- https://go.dev/cl/269658
- https://go.dev/issue/42559
- https://go.googlesource.com/go/+/062e0e5ce6df339dc26732438ad771f73dbf2292
- https://groups.google.com/g/golang-announce/c/NpBGTTmKzpM
- https://groups.google.com/g/golang-announce/c/NpBGTTmKzpM/m/fLguyiM2CAAJ
- https://nvd.nist.gov/vuln/detail/CVE-2020-28366
- https://pkg.go.dev/vuln/GO-2022-0475
- https://www.cve.org/CVERecord?id=CVE-2020-28366
Change history (0)
No recorded changes yet.